ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Data After July 31 Deadline
The ShinyHunters cybercriminal group has publicly claimed responsibility for the recent Ernst & Young (EY) data breach, alleging that it compromised employee credentials and exfiltrated sensitive client information through a supply-chain attack targeting a third-party IT support platform.
The threat actor has issued what it describes as a “final warning,” demanding that EY negotiate before July 31, 2026, or face the public release of the allegedly stolen data.
The claim significantly escalates an incident that was previously disclosed by EY earlier this month and highlights the growing cybersecurity risks associated with third-party service providers and software supply chains.
ShinyHunters Claims EY Data Breach
EY initially revealed the security incident after identifying suspicious activity on April 23, 2026, within an IT service management platform used internally to support tax-related client operations.
Following a forensic investigation, the company determined that an unauthorized third party had accessed the platform between March 28 and April 12, 2026, during which numerous documents linked to EY clients were downloaded.
The affected platform reportedly contained customer support tickets that frequently included sensitive tax documentation submitted by clients for processing.
According to EY’s breach notifications filed with regulatory authorities, the exposed information may include personally identifiable information (PII) and financial records such as names, residential addresses, Social Security numbers, financial account details, credit and debit card information, and other documentation used in the preparation of tax filings.
Although the company confirmed that at least 1,366 individuals across multiple U.S. states were affected based on regulatory reporting requirements, cybersecurity analysts believe the true scope could be significantly larger given EY’s extensive global customer base.
Until recently, the identity of the attackers remained unknown, and EY had not disclosed how the threat actors initially gained access to the third-party environment.
That changed when ShinyHunters added EY to its data leak website alongside newly listed victims including RingCentral and Brink’s Home.
The group claims that the compromise originated through a supply-chain attack that enabled it to obtain credentials providing access to EY’s internal systems.
According to the threat actor, the intrusion was not the result of a direct attack against EY’s infrastructure but rather exploited weaknesses within a trusted external technology provider.
The ransomware and extortion group’s leak-site announcement, updated on July 27, 2026, warns that EY has until July 31 to establish contact before all stolen information is publicly released.
This form of public pressure has become a common tactic among modern cybercriminal organizations, using countdown deadlines to force victims into ransom negotiations while increasing reputational and regulatory pressure.
As of publication, EY has not confirmed the authenticity of ShinyHunters’ claims, nor has the company publicly responded to the group’s ultimatum.
Despite the alleged theft of sensitive information, EY stated that it has found no evidence of fraudulent misuse of the compromised data and believes no individual clients were specifically targeted during the attack.
As a precautionary measure, the firm is offering affected individuals two years of complimentary credit monitoring and identity restoration services while continuing to investigate the incident alongside law enforcement and cybersecurity experts.
ShinyHunters has established itself as one of the most active cyber extortion groups operating in 2026. Rather than relying solely on traditional ransomware deployments, the group increasingly focuses on compromising cloud services, Software-as-a-Service (SaaS) platforms, single sign-on (SSO) credentials, and third-party vendors to gain unauthorized access to enterprise environments.
Security researchers have linked the group’s recent operations to several high-profile breaches involving organizations such as Instructure’s Canvas Learning Management System, Charter Communications, and McGraw Hill, where millions of sensitive records were allegedly stolen before extortion demands were issued.
Researchers also note recurring operational similarities between ShinyHunters and the loosely affiliated Scattered Lapsus$ Hunters collective, both of which frequently leverage social engineering, vishing campaigns, identity provider compromises, and SaaS platform exploitation to bypass traditional perimeter defenses.
These evolving attack methods demonstrate that trusted cloud services and supply-chain ecosystems have become prime targets for financially motivated cybercriminals.
The EY incident serves as another reminder that organizations must extend cybersecurity controls beyond their internal infrastructure to include third-party vendors, cloud platforms, identity systems, and supply-chain partners.
Strengthening vendor risk management, implementing continuous monitoring, enforcing multi-factor authentication, and adopting zero-trust security architectures are becoming essential strategies as threat actors increasingly exploit interconnected business ecosystems to gain access to sensitive enterprise data.
No Comment! Be the first one.